- add
gitbay admin user listto the dashboard (or perhaps a sub-page like/admin/users? might be large on some instances) with administrative actions for users - add an optional setting to email the instance admin upon user signups
admin enhancements #234
Discussion
Second half done in !432: =[registration] notify_admin=, off by default, queues a notice to every instance admin when an account becomes active. Details in the MR and on the Admin wiki page.
First half, =admin user list= on the web, is blocked on a decision that is yours.
Why it is blocked. Every =admin *= command carries =SSHOnly=, and =control.Dispatch= refuses an =SSHOnly= command whenever =ViaAPI= is set. The web dispatcher sets =ViaAPI= on every call, so the page cannot run =admin user list= at all. Today =/admin= renders through =dashboard=, which is why it shows queues and no accounts.
Why that flag is there. The rule on the Parity page is narrower than the flag: "anything whose input is a credential — secrets, mirror tokens, API tokens — stays SSH-only by design". The account commands do not fit it. =admin user list=, =show=, =promote=, =demote=, =disable= and =enable= take a username. The ones that do carry a credential are =user create= (a public key on stdin), =invite= (mails a code) and =email verify= (asserts an address), plus =user delete=, which is permanent.
The catch. =ViaAPI= does not distinguish a browser session from a bearer token, so dropping =SSHOnly= on those six commands also lets a full-scope API token administer the instance. Today no token can, whoever minted it. That is a real widening of what a stolen token is worth, and it is a threat-model call, not a refactor, so I stopped rather than make it.
Three ways forward:
- Drop =SSHOnly= on the six account commands. Simplest, consistent with the written rule, about 60 lines for the page and actions. Cost: a full-scope admin token gains instance administration. Read-only tokens are unaffected, the =ReadOnly= gate already stops them from running the writes.
- Split the flag. Give =Ctx= a =ViaWeb= alongside =ViaAPI=, and let the six run on a browser session while staying off the token API. Keeps the token's blast radius exactly as it is, costs one field, one dispatcher condition and a test asserting the token path still refuses. My recommendation if the widening in 1 bothers you at all, which I think it should.
- Leave it SSH-only and close that half of the issue. The CLI already does all of it, and this instance has one human.
I would take 2. It is barely more work than 1 and it keeps the property that an API token cannot administer the instance, which is worth more than the flag's current bluntness.
Whichever you pick, the page itself is the same: =/admin/users= with the state filter the command takes, keyset paging on the =--cursor= it already returns, a row per account with state, admin mark and last seen, and promote/demote/disable/enable as form posts dispatching the commands. Disable and demote get the typed-name confirm field. Delete and create stay on SSH and the page says so.
closed by cmc in commit 000e6436f3: control: drop SSHOnly, and put the accounts on the admin page
2026-09-19 21:07 UTC
referenced in commit 98cd521512 by cmc: registration: mail the admins when an account becomes active
2026-09-19 19:34 UTC